TLDR
A flaw in Coldcard hardware wallets let attackers drain tens of millions of dollars in Bitcoin from hundreds of users in minutes.
- Attackers exploited a broken random-number generator in Coldcard firmware, stealing around 594 BTC (~3840 million USD) from roughly 500 wallets in a tightly coordinated sweep.
- The bug turned unguessable seeds into guessable ones, triggering one of the biggest self-custody failures yet and raising doubts about single-signature hardware wallet security.
- Bitcoins price reaction has been muted so far, but Coldcard users with seeds from affected firmware now face urgent migration decisions and ongoing investigation risk.
Deep Dive
1. Attack Mechanics And Scale
Reports from multiple analyses show the theft concentrated in a single burst of onchain activity: roughly 594 BTC moved from about 500 single-signature wallets over 2530 minutes, consolidating most funds into a small number of addresses, according to Coindesks incident report.
Galaxy Research and Chainalysis later traced up to 1,196 affected addresses and suggest total losses may approach 1,083 BTC (around 70 million USD) as more linked transactions are identified, as summarized in Bitcoin.coms technical explainer.
Investigators attribute the exploit to a firmware bug in Coldcard devices that disabled proper hardware randomness and fell back to predictable device data (serial number, clock), sharply reducing seed entropy and letting attackers brute-force private keys remotely, as detailed by Decrypts coverage of the vulnerability.
Confidence: high because multiple independent security teams and onchain analytics firms converge on the same mechanics and loss ranges.
2. Impact On Self-Custody
This is one of the clearest examples where a hardware wallet design flaw, not user behavior, directly led to large-scale Bitcoin loss, challenging the perception that cold storage is always safe.
Coldcards maker Coinkite has issued emergency advisories and firmware fixes, but stresses that simply updating does not secure seeds created on vulnerable versions; those seeds remain weak even if imported to another brand of wallet, according to its advisory summarized in Bitcoin.coms Coldcard warning.
Other hardware wallet providers such as Ledger and Trezor have publicly stated they are not affected, pointing to their own randomness designs, while some commentators argue this incident could push more conservative users toward regulated custodians or spot Bitcoin ETFs in the near term.
3. Who Is At Risk Next
Risk is concentrated among Coldcard users whose wallet seeds were generated on specific firmware versions since March 2021, especially Mk3 and early Mk4/Mk5/Q devices, without extra protection like strong BIP-39 passphrases or multisig, per the migration guidance in CryptoPotatos summary of the sweep.
Analysts warn that any seed produced by the flawed generator remains vulnerable even if restored elsewhere, and that attackers may continue scanning for exposed addresses using automated tools, as Chainalysis described in its breakdown of the attacks targeting pattern.
If you ever created a Coldcard wallet on the affected firmware, your risk depends on how that seed was generated and secured; monitoring official Coinkite advisories and independent technical analyses is critical before making any storage changes.
Conclusion
A single randomness bug in a popular hardware wallet turned a core Bitcoin safety assumption on its head, enabling attackers to systematically drain tens of millions of dollars in BTC from long-dormant addresses. While Bitcoins market price has held up so far, the deeper impact is on trust in single-signature self-custody and on how users evaluate wallet security. Over the coming weeks, the key signals will be updated loss estimates, further guidance from security teams, and whether hardware wallet practices evolve toward stronger entropy, independent audits, and more resilient setups.
